Project

General

Profile

Actions

Sub-Task #241

open

Epic #3: Implement a secure user authentication system

Feature #160: User Login

User Story #237: As a user, I want to log in using a security key (WebAuthn), so that I can use phishing-resistant MFA

Store WebAuthn credentials (public key, credential ID, sign count) in the database

Sub-Task #241: Store WebAuthn credentials (public key, credential ID, sign count) in the database

Added by Bricklou about 2 months ago. Updated about 1 month ago.

Status:
Done
Priority:
Normal
Assigned To:
Target version:
Start date:
09/06/2026
Due date:
% Done:

100%

Estimated time:

Description

Store what's needed to recognize and trust each registered security key, per user.

Data kept per key: owning user, user-chosen name, public key, credential identifier, current sign counter, date added, last used date, revoked state.

Behavior:

  • A user can have zero, one, or several keys
  • Revoking a key immediately makes it unusable for login without deleting its history (name/dates remain visible until fully removed if the UX calls for it — otherwise a straight delete is fine)
  • No secret/private key material is ever stored (WebAuthn keeps that on the user's device) — only what's needed to verify future logins
  • Sign counter is updated on every successful login use, and a decrease/repeat is treated as a cloning signal (see #240)
Actions

Also available in: PDF Atom